CVE-2021-36260
KEVCRITICAL 9.8EPSS 99.9%
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 99.87% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-01-10
- Nuclei
- critical · CWE-78
- Published
- 2021-09-22
- Updated
- 2025-10-21
Proof-of-concept exploits (22)
- http://packetstormsecurity.com/files/164603/Hikvision-Web-Server-Build-210702-Command-Inj…
- http://packetstormsecurity.com/files/166167/Hikvision-IP-Camera-Unauthenticated-Command-I…
- https://therecord.media/experts-warn-of-widespread-exploitation-involving-hikvision-camer…
- Aiminsun/CVE-2021-36260299★ · 2021-10-28
- Cuerz/CVE-2021-36260169★ · 2022-08-05
- Miuguel/psychic-chainsaw0★ · 2024-12-02
- NanoTrash/hikvision_brute3★ · 2023-07-29
- Nxychx/TVT-NVR1★ · 2023-01-10
- TaroballzChen/CVE-2021-36260-metasploit20★ · 2021-11-03
- haingn/HIK-CVE-2021-36260-Exploit1★ · 2023-10-22
- mcw0/PoC783★ · 2023-01-12
- naycha/NVR-CONFIG0★ · 2023-01-10
- naycha/TVT-NVR0★ · 2023-01-10
- naycha/TVT-NVR-config1★ · 2023-01-10
- naycha/TVT-config1★ · 2023-01-10
- rabbitsafe/CVE-2021-3626017★ · 2023-10-27
- readloud/PoC0★ · 2022-10-16
- s0duku/PocSelenium0★ · 2021-11-01
- tuntin9x/CheckHKRCE7★ · 2022-10-27
- shubtheone/CVE-2021-36260-hikvision
- yanxinwu946/hikvision-unauthenticated-rce-cve-2021-36260
- kwekre/poc
Nuclei templates (1)
Metasploit modules (1)
ExploitDB entries (1)
Exploit collections (2)
- chaitin/xray/blob/master/pocs/hikvision-unauthenticated-rce-cve-2021-36260.yml
- zan8in/afrog/blob/main/pocs/afrog-pocs/CVE/2021/CVE-2021-36260.yaml